github.com
https://github.com/RobertDra/CVE-2021-31862/blob/main/README.md CVE-2021-31862
MEDIUMNuclei
SysAid 20.4.74 - Cross-Site Scripting
Record summary
CVE-2021-31862 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Proofs of concept
1Repository PoCs
GitHubRobertDra/CVE-2021-31862Repository PoCby RobertDraStars: 3Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMSysAid 20.4.74 - Cross-Site ScriptingCVSS 6.1
SysAid 20.4.74 contains a reflected cross-site scripting vulnerability via the KeepAlive.jsp stamp parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to a patched version of SysAid or apply the vendor-provided security patch to mitigate the XSS vulnerability.
WeaknessesCWE-79
Authorsjas37
Template tagscve2021cvexsssysaidvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sysaid:sysaid:20.4.74:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1540720428
FOFA: icon_hash=1540720428
https://github.com/RobertDra/CVE-2021-31862/blob/main/README.md https://www.sysaid.com/product/on-premise/latest-release https://nvd.nist.gov/vuln/detail/CVE-2021-31862 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-31862 sysaid.com
https://www.sysaid.com/product/on-premise/latest-release